Agent discovery method and device, equipment and storage medium
Patent Information
- Application Number
- CN202610895496.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-22
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2046-06-22
AI Technical Summary
[0005]本申请的主要目的在于提供一种智能体发现方法、装置、设备及存储介质,旨在解决智能体发现过程中安全性和可靠性不足的技术问题
本申请实施例提出了一种智能体发现方法、装置、设备及存储介质,向DHCP服务器发送网络接入请求报文,以使所述DHCP服务器基于所述网络接入请求报文生成DHCP应答报文并发送至客户端;接收所述DHCP服务器发送的DHCP应答报文,基于所述DHCP应答报文与导航智能体之间建立传输连接;向所述导航智能体发送智能体查询请求报文,以使所述导航智能体基于所述智能体查询请求报文获取功能智能体列表信息并发送至所述客户端;接收所述导航智能体发送的所述功能智能体列表信息,基于所述功能智能体列表信息进行验证,验证通过后建立所述客户端和目标功能智能体之间的业务连接。客户端通过DHCP接入获取导航智能体信息并建立连接,再经查询、验证后与功能智能体建立业务连接,实现安全的智能体发现与可信接入。
Smart Images

Figure CN122437878B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to methods, apparatus, devices and storage media for intelligent agent discovery. Background Technology
[0002] With the rapid development of artificial intelligence and the Internet of Things (IoT) technologies, intelligent agents with autonomous decision-making and execution capabilities have become the core computing entities in distributed systems. The dynamic collaboration and mutual discovery capabilities among intelligent agents directly determine the execution efficiency of complex tasks. Currently, intelligent agent discovery mainly relies on pre-configured registries or centralized directory services. In the pre-configured registry approach, the client needs to pre-store the network addresses and identity credentials of all potential functional intelligent agents and initiate connection requests through direct addressing. In the centralized directory service approach, an independent directory server is deployed in the network, and the client retrieves the connection information of functional intelligent agents from the directory server through a standard query protocol, establishing business connections based on the returned results.
[0003] However, the aforementioned existing technical solutions exhibit significant security vulnerabilities in dynamic network environments. In the pre-configured registry solution, the client relies on statically stored address information to directly connect to the functional agent, lacking a real-time verification mechanism for the target agent's identity, making it susceptible to network layer IP spoofing and man-in-the-middle attacks. In the centralized directory service solution, the query interaction between the client and the directory server typically lacks mandatory two-way authentication; the connection information returned by the directory server may be tampered with or forged, causing the client to connect to malicious nodes. None of these solutions effectively decouple network layer address allocation from application layer authentication, making it difficult to guarantee connection reliability during agent discovery in dynamically changing network topologies.
[0004] The above content is only used to help understand the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main objective of this application is to provide a method, apparatus, device, and storage medium for discovering intelligent agents, aiming to solve the technical problems of insufficient security and reliability in the process of discovering intelligent agents.
[0006] To achieve the above objectives, this application proposes an agent discovery method, which is applied to a client and includes: Send a network access request message to the DHCP (Dynamic Host Configuration Protocol) server, so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client; Receive the DHCP response message sent by the DHCP server, and establish a transmission connection with the navigation agent based on the DHCP response message; Send an agent query request message to the navigation agent so that the navigation agent can obtain the list of functional agents based on the agent query request message and send it to the client; The system receives the list of functional agents sent by the navigation agent, performs verification based on the list of functional agents, and establishes a business connection between the client and the target functional agent after successful verification.
[0007] In one embodiment, the step of receiving the DHCP response message sent by the DHCP server and establishing a transmission connection between the DHCP response message and the navigation agent includes: The extended options of the DHCP response message are parsed to extract the authentication domain name, network address, and service parameters of the navigation agent encapsulated in the extended options; Initiate a channel connection to the navigation agent through the network address, and obtain the digital certificate of the navigation agent during the channel connection process; Security verification is performed based on the digital certificate and the authentication domain name. After successful verification, a secure encrypted channel is established between the client and the navigation agent.
[0008] In one embodiment, the step of performing security verification based on the digital certificate and the authentication domain name, and establishing a secure encrypted channel between the client and the navigation agent after successful verification, includes: Extract the user-optional name field from the digital certificate; Based on the public key infrastructure root certificate store built into the client, the legitimacy and validity period of the trust chain of the digital certificate are verified; If the digital certificate is verified, the user's optional name field is compared with the authentication domain name. Once the comparison is successful, a secure encrypted channel is established between the client and the navigation agent.
[0009] In one embodiment, the step of receiving the list of functional agents sent by the navigation agent, verifying based on the list of functional agents, and establishing a service connection between the client and the target functional agent after successful verification includes: Parse the functional agent list information and extract the authentication domain name, network address and connection information of each functional agent entry in the functional agent list information; Based on the connection information, a service connection request is initiated to the target functional intelligent agent, and the digital certificate of the target functional intelligent agent is obtained during the service connection process; The digital certificate is securely verified based on the authentication domain name of the target functional agent. When the security verification is successful, a business connection is established between the client and the target functional agent.
[0010] In one embodiment, after the step of establishing a business connection between the client and the target functional agent upon successful verification, the method further includes: Monitor the connection status of the service connection; When an abnormal interruption is detected in the connection status of the service connection, an updated agent query request message is sent to the navigation agent, so that the navigation agent generates an updated list of functional agents based on the updated agent query request message and sends it to the client. The system receives the updated list of functional agents sent by the navigation agent, performs verification based on the updated list of functional agents, and establishes a business connection between the client and the updated target functional agent after successful verification.
[0011] In one embodiment, the agent discovery method is applied to a DHCP server, and the agent discovery method includes: Receive network access request messages sent by clients, and generate DHCP response messages based on the network access request messages; The DHCP response message is sent to the client so that the client can establish a transmission connection with the navigation agent based on the DHCP response message.
[0012] In one embodiment, the agent discovery method is applied to a navigation agent, and the agent discovery method includes: Receive the agent query request message sent by the client, and obtain the list information of functional agents based on the agent query request message; The list of functional agents is sent to the client so that the client can perform verification based on the list of functional agents. After successful verification, a business connection is established between the client and the target functional agent.
[0013] Furthermore, to achieve the above objectives, this application also proposes an agent discovery device, which includes: The access request sending module is used to send a network access request message to the DHCP server, so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client. The transmission connection establishment module is used to receive the DHCP response message sent by the DHCP server and establish a transmission connection with the navigation agent based on the DHCP response message; The query request sending module is used to send an agent query request message to the navigation agent, so that the navigation agent can obtain the functional agent list information based on the agent query request message and send it to the client. The service connection establishment module is used to receive the list information of the functional intelligent agents sent by the navigation intelligent agent, perform verification based on the list information of the functional intelligent agents, and establish a service connection between the client and the target functional intelligent agent after successful verification.
[0014] In addition, to achieve the above objectives, this application also proposes an agent discovery device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the agent discovery method as described above.
[0015] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the intelligent agent discovery method as described above.
[0016] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the agent discovery method described above.
[0017] One or more technical solutions proposed in this application have at least the following technical effects: This application proposes a method, apparatus, device, and storage medium for agent discovery. The method involves sending a network access request message to a DHCP server, causing the DHCP server to generate a DHCP response message and send it to the client; receiving the DHCP response message from the DHCP server and establishing a transmission connection with a navigation agent based on the DHCP response message; sending an agent query request message to the navigation agent, causing the navigation agent to obtain a list of functional agents based on the agent query request message and send it to the client; receiving the list of functional agents from the navigation agent, verifying the list of functional agents, and establishing a service connection between the client and the target functional agent after successful verification. The client obtains navigation agent information and establishes a connection through DHCP access, and then establishes a service connection with the functional agent after querying and verification, thus achieving secure agent discovery and trusted access. Attached Figure Description
[0018] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0019] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating an embodiment of the intelligent agent discovery method of this application. Figure 2 A simplified flowchart illustrating the agent discovery method provided in this application embodiment; Figure 3 This is a schematic diagram of the module structure of the intelligent agent discovery device according to an embodiment of this application; Figure 4 This is a schematic diagram of the device structure of the hardware operating environment involved in the agent discovery method in this application embodiment.
[0021] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0022] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0023] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0024] The main solution of this application embodiment is as follows: A network access request message is sent to a DHCP server, so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client; the DHCP response message sent by the DHCP server is received, and a transmission connection is established between the DHCP response message and the navigation agent; an agent query request message is sent to the navigation agent, so that the navigation agent obtains the functional agent list information based on the agent query request message and sends it to the client; the functional agent list information sent by the navigation agent is received, verification is performed based on the functional agent list information, and a service connection is established between the client and the target functional agent after successful verification.
[0025] In this embodiment, for ease of description, the following description uses the intelligent agent discovery device as the execution subject.
[0026] With the rapid development of artificial intelligence and the Internet of Things (IoT) technologies, intelligent agents with autonomous decision-making and execution capabilities have become the core computing entities in distributed systems. The dynamic collaboration and mutual discovery capabilities among intelligent agents directly determine the execution efficiency of complex tasks. Currently, intelligent agent discovery mainly relies on pre-configured registries or centralized directory services. In the pre-configured registry approach, the client needs to pre-store the network addresses and identity credentials of all potential functional intelligent agents and initiate connection requests through direct addressing. In the centralized directory service approach, an independent directory server is deployed in the network, and the client retrieves the connection information of functional intelligent agents from the directory server through a standard query protocol, establishing business connections based on the returned results.
[0027] However, the aforementioned existing technical solutions exhibit significant security vulnerabilities in dynamic network environments. In the pre-configured registry solution, the client relies on statically stored address information to directly connect to the functional agent, lacking a real-time verification mechanism for the target agent's identity, making it susceptible to network layer IP spoofing and man-in-the-middle attacks. In the centralized directory service solution, the query interaction between the client and the directory server typically lacks mandatory two-way authentication; the connection information returned by the directory server may be tampered with or forged, causing the client to connect to malicious nodes. None of these solutions effectively decouple network layer address allocation from application layer authentication, making it difficult to guarantee connection reliability during agent discovery in dynamically changing network topologies.
[0028] This application provides a solution in which the client obtains navigation agent information and establishes a connection through DHCP access, and then establishes a business connection with the functional agent after querying and verification, thereby realizing secure agent discovery and trusted access.
[0029] It should be noted that the executing entity in this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, or mobile phone, or an electronic device or intelligent agent discovery device capable of performing the above functions. The following description uses an intelligent agent discovery device as an example to illustrate this embodiment and the subsequent embodiments.
[0030] Based on this, embodiments of this application provide a method for discovering intelligent agents, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the intelligent agent discovery method of this application.
[0031] In this embodiment, the agent discovery method is applied to the client, and the agent discovery method includes steps S11 to S14: Step S11: Send a network access request message to the DHCP server so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client.
[0032] It should be noted that a network access request message refers to a Discover or Solicit message generated by a client when accessing a local area network (LAN) according to the DHCP (Dynamic Host Configuration Protocol) specification. This message contains an option request to obtain navigation agent configuration information, explicitly declaring that the client supports and requests agent service configuration; the option request is expressed as an option code. The DHCP server is a network infrastructure node within the LAN responsible for centrally managing IP addresses and configuration parameters.
[0033] Additionally, it should be noted that a client refers to a terminal device or software entity that actively initiates network access requests, agent discovery requests, and ultimately, service invocation requests when connected to a local area network or zero-trust network environment. It supports DHCP protocol extended option parsing, X.509 certificate verification, and secure encrypted communication with agents, and is a service request node in the agent discovery architecture. For example, the client could be an industrial data acquisition terminal or industrial robot in a smart manufacturing workshop, a smart speaker or smart control screen in a smart home scenario, or a user's smart mobile device such as a mobile phone.
[0034] Understandably, this step achieves synchronous triggering of network configuration and agent discovery by embedding a pre-request for agent service discovery into the standard network access process. This design moves the entry point for agent discovery to the network layer, avoiding the delays of relying on upper-layer applications to initiate discovery separately in traditional solutions, thus solving the problem of low agent access efficiency at its source.
[0035] Specifically, before initiating a DHCP request, the client first completes 802.1X port authentication. After successful authentication, it connects to the network. Upon connecting, the client first sends a DHCPv4 Discover message via broadcast or multicast. In the Options field of this message, the client fills in a custom option code (e.g., defining Option 224). This option code informs the DHCP server that the client requires not only the regular IP address configuration but also the configuration information for the navigation agent. Upon receiving this request, the DHCP server records the client's MAC address and the requested options.
[0036] For example, client A accesses the smart manufacturing workshop network, sends a DHCP Discover message, and includes the Agent-Discovery-Request flag in the options.
[0037] Step S12: Receive the DHCP response message sent by the DHCP server, and establish a transmission connection with the navigation agent based on the DHCP response message.
[0038] It should be noted that a DHCP response message refers to an Offer or Reply message from the DHCP server, which contains extended options. These extended options encapsulate the core connection parameters of the navigation agent. The fields of the extended options include option code, option length, service priority, authentication domain name length, the navigation agent's authentication domain name (ADN), address length, one or more IP addresses, and service parameters (SvcParams). The service parameters include the Application Layer Protocol Negotiation (ALPN) identifier and port number, URI path, and are encoded according to a preset service parameter data format to instruct the client on the communication protocol for establishing the underlying connection. The transport connection at this stage specifically refers to the underlying network connection between the client and the navigation agent, typically established based on TCP (Transmission Control Protocol) or UDP (User Datagram Protocol).
[0039] Additionally, it's important to note that the navigation agent, within a DHCP-based agent discovery architecture, acts as a special management node serving as a "dynamic directory" or "main unit" for agents across the entire local area network. It possesses core functions such as maintaining agent registration information, retrieving and matching functional agents, and returning functional agent information to clients. Furthermore, it supports authentication and encrypted communication with clients based on X.509 certificates, acting as a navigation node connecting clients and functional agents. Examples include AI service registration centers deployed on enterprise gateways, industrial servers deployed in smart manufacturing workshop LANs, and edge computing gateways in smart home LANs. These devices all have built-in agent registration and retrieval modules, enabling dynamic matching and list return of functional agents.
[0040] Understandably, this step leverages the inherent push mode of the DHCP protocol to directly send the navigation agent's addressing information to the client, eliminating the need for the client to query the navigation agent via external DNS or hard-coded methods. This mechanism effectively decouples network addressing from application-layer trust verification, preventing the risk of man-in-the-middle attacks introduced by reliance on external resolvers.
[0041] Specifically, after receiving the DHCP response message, the client verifies its digital signature, timestamp, and random number. If valid, it parses out the extended options. These options include a list of IP addresses for the navigation agent, the Authentication Domain Name (ADN), and the service port. The client then selects one of the IP addresses and initiates a TCP connection request using the resolved port number, beginning the handshake process for the underlying transport channel. This transport channel is a bidirectional mTLS (mutually linked TLS) secure encrypted channel. Bidirectional mTLS is a secure communication method that adds a client authentication mechanism to the standard TLS encrypted channel. It requires both parties (e.g., server and client) to verify not only the server's certificate to confirm its identity but also the certificate provided by the client when establishing an encrypted connection, thus ensuring mutual trust between the two ends. This combination of bidirectional authentication and encrypted transmission effectively prevents man-in-the-middle attacks, unauthorized device access, and eavesdropping on communication content.
[0042] Meanwhile, after receiving the DHCP response message, the client verifies the digital signature, timestamp, and random number in the response message to confirm that the message has not been tampered with and is not a replay attack.
[0043] For example, client A resolves the IP address of the navigation agent as 192.168.1.100 and the port number as 8443 from the extended field of the DHCP response message, and then initiates a TLS (Transport Layer Security) handshake connection to that address.
[0044] Step S13: Send an agent query request message to the navigation agent so that the navigation agent can obtain the list of functional agents based on the agent query request message and send it to the client.
[0045] It should be noted that the agent query request message is an application-layer data packet sent by the client to the navigation agent through an established transmission channel. This message carries business metadata used to filter functional agents, such as agent category and required Quality of Service (QoS) level.
[0046] Additionally, it should be noted that a functional intelligent agent refers to an autonomous computing entity with a specific role definition, inherent capabilities, and knowledge model, responsible for receiving instructions from clients and executing specific business tasks. Functional intelligent agents are the endpoints in the entire network architecture that ultimately provide actual business functions (such as data computation and device control). Examples include a "security detection intelligent agent" specifically responsible for handling network traffic analysis, a "smart temperature control intelligent agent" responsible for regulating the indoor environment, or a "large language model microservice node" performing complex logical operations.
[0047] Understandably, this step passes specific business requirements to the navigation agent, which acts as a dynamic directory. Leveraging the navigation agent's centralized management capabilities, it achieves a leap from generalized network access to refined service function matching. Compared to the client performing a full network scan on its own, this approach significantly reduces network overhead and improves matching accuracy.
[0048] Specifically, after the transmission connection is established, the client constructs an agent query request based on HTTP / JSON or gRPC format. The request body contains key-value pairs such as agent_type: temperature_control and location: zone_A. The client sends this request to the navigation agent through the established encrypted channel.
[0049] For example, the smart home central control screen (client) sends a query request to the navigation smart agent, requesting to find the air conditioner smart agent that is currently online and supports infrared control.
[0050] Step S14: Receive the list of functional agents sent by the navigation agent, verify based on the list of functional agents, and establish a business connection between the client and the target functional agent after successful verification.
[0051] It should be noted that the list of functional agents is structured data returned by the navigation agent, typically containing entries for multiple candidate functional agents. Verification specifically refers to the two-way authentication process based on X.509 certificates and the authentication domain name of the functional agents.
[0052] Understandably, this step transforms traditional IP-based untrusted connections into identity-based encrypted connections by introducing an authenticated domain name as a trust anchor. By rigorously verifying the certificates of the functional agents, it ensures that the business endpoint ultimately connected to by the client is authentic and trustworthy, thereby resolving the security issue of agent identity forgery in a distributed environment.
[0053] Specifically, the client parses the returned list of functional agents, verifies the signature, and decrypts it. Then, it selects a functional agent as the target and verifies its certificate chain, SAN domain name, and revocation status based on the functional agent list information. If verification is successful, the client initiates a TLS connection to the functional agent using the IP address and port from the list. During the TLS handshake, the client obtains the functional agent's digital certificate, extracts its SAN (Subject Alternative Name) field, and compares it with the authenticated domain names in the list. If the comparison matches and the certificate chain verification passes, the final HTTPS or encrypted gRPC service connection is established.
[0054] For example, after receiving the list, the client selects the air conditioner smart agent with the certified domain name ac.example.com, verifies that it is ac.example.com by verifying the user optional name field in its certificate, and then establishes a business connection and sends a temperature adjustment command.
[0055] This embodiment, through the above-described scheme, constructs a three-tier architecture of DHCP bootstrapping, navigation agent relaying, and functional agent direct connection, achieving a fully automated process from network access to service invocation on the client side. This method leverages the inherent broadcast characteristics of DHCP to solve the initial addressing problem, utilizes the navigation agent to address the dynamic directory issue, and finally solves the identity trust problem by binding certificates and authentication domain names. Overall, it achieves millisecond-level plug-and-play functionality and secure access for the agents.
[0056] Based on the above implementation scheme, in one feasible implementation, the step of receiving the DHCP response message sent by the DHCP server and establishing a transmission connection between the DHCP response message and the navigation agent includes S21~S23: Step S21: Parse the extended options of the DHCP response message and extract the authentication domain name, network address and service parameters of the navigation agent encapsulated in the extended options.
[0057] It should be noted that extended options refer to fields reserved in the standard DHCP protocol message structure for carrying vendor-defined information. In this scheme, this field is designed as a binary data stream containing a specific type-length-value structure. The authentication domain name is a unique string used to identify the navigation agent and will be used for certificate verification later; service parameters typically include the Application Layer Protocol Negotiation (ALPN) identifier and the port number.
[0058] Understandably, this step involves dissecting the deeper content of the DHCP response message. Since the DHCP protocol itself does not restrict the format of extended options, a strict set of parsing rules needs to be defined to accurately map the binary stream into configuration objects recognizable by the client. The accuracy of this step directly determines whether a correct connection to a legitimate navigation agent can be established subsequently.
[0059] Specifically, after receiving the DHCP response message, the client iterates through the Option list in the message and locates the pre-agreed agent discovery option code (such as Option 224). Then, the client reads the subsequent bytes according to a preset format: first, it reads the 1-byte service priority, then the 2-byte authentication domain name length field, then the UTF-8 encoded bytes of the authentication domain name string according to the length, and finally the remaining service parameter structure.
[0060] For example, the client parses the Option 224 field, reads that the authentication domain name is 13 bytes long, corresponding to the string nav.example.com, and then reads that the port number is 8443 and the protocol type is h2 (HTTP / 2).
[0061] Step S22: Initiate a channel connection to the navigation agent through the network address, and obtain the digital certificate of the navigation agent during the channel connection process.
[0062] It should be noted that the channel connection here specifically refers to the Transport Layer Security (TLS) handshake process. In this process, the client acts as a TLS client, and the navigation agent acts as a TLS server; both parties negotiate the encryption algorithm and session key by exchanging handshake messages. A digital certificate is an identity credential issued to the navigation agent by a trusted Certificate Authority (CA), containing a public key and identity information.
[0063] Understandably, this step aims to establish a confidential and integrity-protected transmission channel. By forcibly acquiring and verifying the other party's digital certificate at the initial stage of connection establishment, passive eavesdropping and active man-in-the-middle attacks in the network can be effectively prevented, providing security for subsequent application layer data exchange.
[0064] Specifically, the client uses the IP address and port number resolved in step S201 to initiate a TCP connection by calling the operating system's underlying Socket API. Once the TCP three-way handshake is complete, the client immediately sends a TLS ClientHello message. When responding to the ServerHello message, the navigation agent packages its X.509 certificate chain into a Certificate message and sends it to the client.
[0065] For example, the client initiates a connection to IP 10.0.0.1:8443 and receives a certificate packet containing the public key and identity information from the navigation agent during the Certificate phase of the TLS handshake.
[0066] Step S23: Perform security verification based on the digital certificate and the authentication domain name. After successful verification, establish a secure encrypted channel between the client and the navigation agent.
[0067] It should be noted that security verification is a complex verification process, which includes at least the trust chain verification of the certificate chain, validity period verification, and identity binding verification. A secure encrypted channel refers to a logical channel where, after a TLS handshake negotiation, both parties possess a shared session key, and all application layer data is transmitted using this key with symmetric encryption.
[0068] Understandably, this step is central to establishing trust. Simply possessing a certificate is insufficient; it must be proven that the certificate truly belongs to the navigation agent claimed by the DHCP server. By strongly binding and verifying the identity identifier (user-selectable name) in the certificate with the authentication domain name issued by DHCP, dual verification of network layer addressing and application layer identity is achieved.
[0069] Specifically, upon receiving the certificate, the client performs two-way authentication based on the digital certificate and the authentication domain name. It then verifies the certificate against the OCSP (Online Certificate Status Protocol) and CRL (Certificate Revocation List) to ensure it hasn't been revoked. First, it verifies the validity of the certificate signature chain using its local built-in PKI root certificate store and checks the certificate's Not Before and Not After timestamps. If the verification passes, the client further extracts the optional user name extension field from the certificate and compares it with the extracted authentication domain name string using a case-insensitive but character-matching comparison. After successful verification, a secure encrypted channel is established between the client and the navigation agent.
[0070] In actual deployment, the navigation agent can be a single node or a multi-active cluster composed of multiple nodes. Cluster nodes synchronize agent registration information through consensus protocols such as Raft to avoid single points of failure.
[0071] For example, the client verifies that the root CA of the certificate chain is the Enterprise Root CA and that the certificate has not expired. At the same time, the DNSName in the optional name field of the certificate user is exactly equal to nav.example.com. The verification is successful, and both parties complete the TLS handshake and establish a secure encrypted channel.
[0072] This embodiment, through the above scheme, obtains identity and address information by parsing extended options, and then combines TLS handshake and certificate verification mechanisms to establish a secure connection between the client and the navigation agent from scratch and from untrusted to trusted, laying a solid security foundation for subsequent agent queries.
[0073] Based on the above implementation scheme, in one feasible implementation, the step of performing security verification based on the digital certificate and the authentication domain name, and establishing a secure encrypted channel between the client and the navigation agent after successful verification, includes S31~S33: Step S31: Extract the user optional name field from the digital certificate.
[0074] It should be noted that the digital certificate in this scheme follows the X.509 v3 international standard format. The Subject Alternative Name is an extended field in the X.509 certificate that allows the certificate holder to bind one or more identity identifiers (such as DNS names, IP addresses, and URIs) to the public key. In this scheme, the Subject Alternative Name field is primarily used to carry the authentication domain name (authentication domain name) of the navigation agent.
[0075] Understandably, in Public Key Infrastructure (PKI) systems, the Subject field of a certificate often contains only a generic name, which is insufficient to handle complex multi-domain or multi-service scenarios in modern cybersecurity practices. The introduction of the optional user name field provides a more flexible and standardized identity binding mechanism. Extracting this field is a prerequisite for implementing authentication based on the certified domain name.
[0076] Specifically, after receiving the certificate data structure during the TLS handshake, the client calls the parsing interface of a cryptographic library (such as OpenSSL or Bouncy Castle) to traverse the list of certificate extensions and locate the User Optional Name extension for the object identifier. Subsequently, the client decodes the encoded data of this extension into a readable list of objects and extracts the entries of type dNSName (DNS name).
[0077] Step S32: Based on the public key infrastructure root certificate store built into the client, verify the legitimacy and validity period of the trust chain of the digital certificate.
[0078] It should be noted that the Public Key Infrastructure (PKI) root certificate store is a pre-installed set of self-signed certificates from trusted root certificate authorities in the client system. Trust chain legitimacy means that the certificate to be verified must have been directly or indirectly issued by a root certificate authority within the root certificate store. Validity refers to whether the certificate is within the time window of its effective and expiration dates under the current system time.
[0079] Understandably, this is fundamental to establishing trust. If a certificate is not issued by a trusted certificate authority, or if it has expired or is not yet valid, then the entity corresponding to that certificate, regardless of who it claims to be, is untrustworthy. This step filters out the vast majority of forged and invalid certificates, serving as the first line of defense for system security.
[0080] Specifically, the client submits the received certificate chain (including the terminal entity certificate and several intermediate certificate authority certificates) to the certificate verification engine. The engine verifies the signatures level by level, starting from the terminal certificate, until it finds a certificate issuer that happens to exist in the client's built-in root certificate store. At the same time, the engine checks whether the system's current time is within the certificate's validity period.
[0081] Step S33: If the digital certificate is verified, the user's optional name field is compared with the authentication domain name. If the comparison is successful, a secure encrypted channel is established between the client and the navigation agent.
[0082] It should be noted that the comparison operation refers to an exact match of strings. In this scheme, at least one entry in the user's optional name field must be exactly the same as the authentication domain name string issued by DHCP (case-insensitive, but the character sequence must be identical). The establishment of a secure encrypted channel marks the end of the TLS handshake process, and both parties enter the encrypted data transmission phase.
[0083] Understandably, this is a crucial step in binding network layer information (the authentication domain name issued by DHCP) with application layer identity (the user-optional name in the certificate). Even if the certificate itself is valid, the connection will still be rejected if it does not belong to the navigation agent specified by the DHCP server (i.e., the authentication domain name does not match). This reduces the attack scenario of a valid certificate but an incorrect host.
[0084] Specifically, after successful verification, the client iterates through the extracted list of possible user names. For each dNSName in the list, the client compares it with the authentication domain name variable stored in memory using a string comparison function (such as strcmp or equalsIgnoreCase). As long as any entry is found to be a complete match with the authentication domain name, the identity verification is considered successful, and the TLS handshake is allowed to continue until completion.
[0085] This embodiment uses the above-described scheme to ensure the authenticity of the certificate through certificate chain verification and to ensure the consistency between the certificate and the expected service by comparing the user's optional name with the authentication domain name. This achieves high-strength two-way identity authentication between the client and the navigation agent, effectively defending against man-in-the-middle attacks and phishing attacks.
[0086] Based on the above implementation scheme, in one feasible implementation, the steps of receiving the list of functional agents sent by the navigation agent, verifying based on the list of functional agents, and establishing a business connection between the client and the target functional agent after successful verification include S41~S43: Step S41: Parse the functional agent list information and extract the authentication domain name, network address and connection information of each functional agent entry in the functional agent list information.
[0087] It should be noted that the authentication domain name here refers to the authentication domain name of the functional agent; the network address mainly refers to the IP address of the functional agent; the connection information is a composite concept, including the list of IP addresses of the functional agent, protocol type, port number and optional URI path, and the metadata includes the capability description and service level of the functional agent.
[0088] Understandably, the navigation agent returns a list containing multiple candidates, from which the client needs to filter out the target that best meets the current business requirements. This step involves deserializing and extracting fields from the list data, providing raw data support for subsequent concurrent connection attempts or optimal selection.
[0089] Specifically, the client receives the response functional agent list information message through the established encrypted channel. The client calls the parser to convert the string into an object tree. Subsequently, the client traverses the array nodes in the object tree, and for each array element, reads the authentication domain name, network address, and connection information of each functional agent entry in its functional agent list information.
[0090] Step S42: Initiate a service connection request to the target functional agent based on the connection information, and obtain the digital certificate of the target functional agent during the service connection process.
[0091] It should be noted that a business connection request refers to a connection initiated by the client to call a specific functional service, which is different from a management connection with the navigation agent. This connection is also based on security protocols such as TLS. A digital certificate is the identity credential presented by the target functional agent during the TLS handshake phase. In one embodiment of this application, the digital certificate is an X.509 certificate. An X.509 certificate is a digital certificate format conforming to the International Telecommunication Union (ITU-T) X.509 standard, used in computer network communication to achieve entity authentication and encrypted communication through public key infrastructure. Essentially, it is a structured data file containing a public key, holder identity information, issuing authority information, validity period, and extended fields (such as SAN), and is digitally signed by a trusted certificate authority to ensure its authenticity and integrity. In the agent discovery method of this invention, the X.509 certificate is used in the authentication process when the client establishes a connection with the navigation agent and functional agents. By verifying the legality of the certificate chain and comparing the user's optional name extracted from the certificate with the authentication domain name, the authenticity and trustworthiness of the communication peer are ensured, effectively preventing man-in-the-middle attacks.
[0092] Understandably, this step marks the client's formal transition from the service discovery phase to the service invocation phase. The client no longer interacts with the navigation agent but instead establishes a secure, peer-to-peer connection directly with the final business provider. This process reuses a TLS handshake mechanism similar to the navigation agent authentication, ensuring consistency in security policies.
[0093] Specifically, the client constructs a corresponding connection request based on the extracted protocol type (such as HTTPS). If the protocol is HTTPS, the client initiates a TCP connection to the extracted IP address and port, and then immediately starts the client greeting message process, such as the TLS ClientHello process. The target functional agent sends its own X.509 certificate when responding to the TLS handshake.
[0094] Step S43: Perform security verification on the digital certificate based on the authentication domain name of the target functional agent. When the security verification is successful, establish a business connection between the client and the target functional agent.
[0095] It should be noted that security verification here specifically refers to the authentication of functional agents. The logic is similar to that used when verifying navigation agents, but the verification object is the binding relationship between the functional agent's authentication domain name and the optional name field of the digital certificate user. Business connection refers to the final connection channel that enables application-layer data exchange (such as sending API requests and receiving business data).
[0096] Understandably, this is the final security checkpoint in the entire discovery process. Because functional agents can be numerous, widely distributed, and even dynamically started and stopped, rigorous identity verification is essential for each final business endpoint. Only after confirming the true identity of the business endpoint can business commands or sensitive data be safely sent.
[0097] Specifically, after receiving the certificate from the target functional agent, the client performs certificate chain verification, SAN matching, and revocation status checks on the digital certificate based on the target functional agent's authentication domain name. First, the certificate chain and validity period are verified. Then, the user optional name field is extracted from the certificate. Finally, the user optional name field is precisely compared with the extracted authentication domain name of the functional agent. Only after the comparison matches and the security verification is confirmed, does the client consider the connection secure and then send specific business requests to establish a business connection between the client and the target functional agent.
[0098] For example, the user optional name field in the client verification function agent certificate contains temp.acme.com and is consistent with the authentication domain name in the list. After successful verification, a control command to set the temperature to 26 degrees Celsius is sent through the HTTPS connection.
[0099] This embodiment, through the above scheme, obtains the target identity and address by parsing a structured list, and then confirms the target identity through a standardized TLS certificate verification mechanism, thereby realizing a secure and reliable business connection between the client and the functional intelligent agent, and completing the closed loop of the entire intelligent agent discovery and access process.
[0100] Based on the above implementation scheme, in one feasible implementation, after the step of establishing the business connection between the client and the target functional intelligent agent after successful verification, the method further includes steps S51 to S53: Step S51: Monitor the connection status of the service connection.
[0101] It should be noted that the business connection refers to the secure and encrypted channel established between the client and the target functional agent. The connection status includes, but is not limited to: the keep-alive status of the TCP connection, the response status of heartbeat packets, the transmission delay and packet loss rate of application layer data, and whether an abnormal disconnection has occurred, such as a connection reset event or a connection termination event.
[0102] Understandably, in dynamic network environments and agent lifecycles, functional agents may go offline or change addresses due to load migration, software upgrades, or hardware failures. Continuously monitoring connection status is essential to ensure business continuity, enabling timely detection of signs of service interruption and triggering reconnection or switching mechanisms.
[0103] Specifically, the client can start a background monitoring thread or timer at the application layer. This monitoring logic periodically sends application-layer heartbeat packets (Ping / Pong) to the peer, or listens for exception callback events of the underlying Socket (network socket event). If no response is received within the preset timeout period, or a connection reset exception is captured, it is determined that the connection status is abnormal.
[0104] For example, the client sends a heartbeat request to the functional agent every 30 seconds. If no response is received for three consecutive times, the current connection is marked as unhealthy.
[0105] Step S52: When an abnormal interruption is detected in the connection status of the service connection, an updated agent query request message is sent to the navigation agent, so that the navigation agent generates an updated list of functional agents based on the updated agent query request message and sends it to the client.
[0106] It should be noted that abnormal interruption refers to a situation where the connection is unavailable but not properly closed. The updated agent query request message may contain the same or different business metadata as the initial query, but in this step, the core is to reuse the existing navigation agent channel and trigger a new discovery process.
[0107] Understandably, this step leverages the advantages of the navigation agent as a dynamic directory. When backend services change, the client doesn't need to re-perform the DHCP discovery process; it only needs to send a lightweight query to the navigation agent to obtain the latest service endpoint information. This mechanism significantly reduces service recovery time and enables seamless dynamic updates.
[0108] Specifically, once a connection anomaly is detected, the client immediately sends a new query request through the secure, encrypted channel previously established and maintained with the navigation agent. This request can carry the same filtering criteria as the initial query, or the filtering criteria can be adjusted based on the current network conditions or business needs (such as requesting a higher-priority backup agent).
[0109] For example, the client detects that the connection with the air conditioning agent has been lost, and then sends a request to the navigation agent through the existing TLS channel: Please find the currently available air conditioning agent again.
[0110] Step S53: Receive the updated list of functional agents sent by the navigation agent, perform verification based on the updated list of functional agents, and establish a business connection between the client and the updated target functional agent after successful verification.
[0111] It should be noted that the updated list of functional agents reflects the latest network topology and service status perceived by the navigation agent. The entries in this list may be completely different from the initial list.
[0112] Understandably, this step verifies the repeatability of the entire discovery mechanism, ensuring that clients can always find and connect to available services through a standardized process, even when the network environment changes dynamically, thereby achieving system self-healing and high availability.
[0113] Specifically, after receiving the new list, the client parses the new list, extracts the authentication domain name and connection information of the new target functional agent, initiates a new TLS connection, verifies the certificate and authentication domain name, establishes a new business connection after the verification is successful, and resumes data transmission.
[0114] For example, the navigation agent returns a new list of air conditioning agents, and the client selects the entry with the authentication domain name ac-backup.example.com, completes the verification, establishes a new business connection, and continues to perform the temperature control task.
[0115] This embodiment, through the above-described scheme, continuously monitors the health of service connections and automatically triggers a re-query process with the navigation agent when anomalies occur, thereby enabling the client to adapt to network fluctuations and dynamic changes in functional agents. This design significantly improves the system's robustness and service continuity in complex and unstable network environments, meeting the requirements for high-availability agent collaboration.
[0116] Based on the above implementation scheme, in one feasible implementation, the agent discovery method is applied to a DHCP server, and the agent discovery method includes steps S61-S62: Step S61: Receive the network access request message sent by the client, and generate a DHCP response message based on the network access request message.
[0117] It should be noted that a network access request message refers to a request message sent by a client according to the Dynamic Host Configuration Protocol (DHCP) specification, which includes custom options for requesting agent configuration. A DHCP response message refers to an Offer or Reply message responded by the DHCP server, which includes extended options. These extended options encapsulate the core connection parameters of the navigation agent. The fields of the extended options include option code, option length, service priority, authentication domain name length, the navigation agent's authentication domain name, address length, one or more IP addresses, and service parameters. The service parameters include an application layer protocol negotiation identifier and port number, URI path, and are encoded according to a preset service parameter data format to instruct the client on the communication protocol for establishing the underlying connection. Simultaneously, the DHCP response message carries a digital signature, timestamp, and random number.
[0118] Understandably, this step involves the DHCP server interpreting and responding to the client's intent. By embedding logic for recognizing custom options into the standard DHCP process, the server can distinguish between ordinary clients and clients with intelligent agent capabilities, thereby determining whether additional intelligent agent configuration information needs to be injected into the response.
[0119] Specifically, after receiving a network access request message broadcast by a client on its listening port (such as UDP 67), the DHCP server parses the message payload. The server checks whether a pre-agreed agent discovery option code (such as Option 224) exists in the options field. If it does, the server records the client's MAC address and hardware information, preparing to generate a response message containing extended configuration.
[0120] For example, when the DHCP server receives a message from a client with a MAC address of 00:11:22:33:44:55, it detects that the message contains Option 224 and determines that the client supports the agent discovery function.
[0121] Step S62: Send the DHCP response message to the client so that the client establishes a transmission connection with the navigation agent based on the DHCP response message.
[0122] It should be noted that the sending action in the DHCP protocol usually involves unicast or broadcast, depending on the client's network status.
[0123] Understandably, the DHCP server is not only the manager of IP addresses, but also the informer of the network topology of the intelligent agents. By encapsulating the connection parameters of the navigation agents in the response messages, the server points out the entry point to the intelligent agent network for the client before the client has obtained an IP address, thus realizing atomic operations for network configuration and service discovery.
[0124] Specifically, the DHCP server constructs a DHCP response message. In the Options field of the message, in addition to filling in standard IP address lease information, a custom extended option is also filled in. This extended option is encoded in TLV format and contains the navigation agent's authentication domain name, a list of IP addresses, and service parameters. Finally, the server sends the message over the network.
[0125] In this embodiment, by adding the ability to perceive and respond to agent configuration options to the standard network access protocol processing flow, the DHCP server becomes the primary driving force of the entire agent network, providing clients with zero-configuration, low-latency initial boot services and solving the addressing problem when agents are deployed on a large scale.
[0126] Based on the above implementation scheme, in one feasible implementation, the agent discovery method is applied to a navigation agent, and the agent discovery method includes S71~S72: Step S71: Receive the agent query request message sent by the client, and obtain the functional agent list information based on the agent query request message.
[0127] It should be noted that the agent query request message is an application-layer request sent by the client through a secure encrypted channel. The process of obtaining the list of functional agents may involve two mechanisms: one is querying the static registry maintained in the local memory or database of the navigation agent; the other is real-time dynamic discovery within the local area network through multicast, broadcast, or active probing.
[0128] Understandably, this step embodies the core value of the navigation agent as a dynamic directory. It abstracts the complexity of the backend functional agents, providing a unified query interface. Whether it's static registration or dynamic discovery, the goal is to allow clients to focus solely on their business requirements without needing to concern themselves with the deployment details of backend services.
[0129] Specifically, the navigation agent receives query requests from clients through its open interfaces, such as HTTPS or gRPC. The navigation agent parses the business metadata in the request body. Subsequently, the navigation agent executes a matching algorithm in its internal agent registry to filter out all functional agent instances that meet the criteria.
[0130] For example, when a navigation agent receives a query request to find a visual analysis agent that supports 4K video streaming, it then searches the registry for online agents with the tag "vision" and a computing power rating of "high".
[0131] Step S72: Send the list of functional agents to the client so that the client can verify based on the list of functional agents. After successful verification, establish a business connection between the client and the target functional agent.
[0132] It should be noted that the transmission is conducted through a previously established secure encrypted channel, ensuring the confidentiality of the list information during transmission. The list of functional agents is structured data that has been formatted (e.g., JSON / Protobuf), containing key information such as the authentication domain name, IP address, and port of each candidate agent.
[0133] Additionally, it should be noted that a functional agent refers to an autonomous computing entity with a specific role definition, inherent capabilities, and knowledge model, responsible for receiving instructions from clients and executing specific business tasks. Functional agents are the endpoints in the entire network architecture that ultimately provide actual business functions (such as data computation and device control). Examples include a security detection agent specifically responsible for handling network traffic analysis, an intelligent temperature control agent responsible for regulating the indoor environment, or a large language model microservice node performing complex logical operations. Detailed information for each functional agent entry must include an authentication domain name, IP address, connection information, and metadata. The authentication domain name serves as the unique identifier of the functional agent; there must be at least one IP address (IPv4 or IPv6); connection information includes the service port number, connection protocol type (such as HTTP / CoAP), and an optional URI path; the metadata describes the functional agent's service capabilities, service level, and current status.
[0134] Understandably, this step marks the end of the navigation agent's intermediary role. It delivers the internally matched results to the client in a standardized and secure manner. Once the client receives this list, it can bypass the navigation agent and directly establish a point-to-point business connection with the functional agent, thereby achieving efficient decentralized communication.
[0135] Specifically, the navigation agent assembles the matching results into an array object. Each array element represents a functional agent. The navigation agent calls the encrypted channel's sending interface, encrypts the functional agent list information, attaches a digital signature, and returns it as response data to the client. The client parses the returned functional agent list information and selects a functional agent as the target. Subsequently, the client initiates a TLS connection to the functional agent using the IP address and port from the list. During the TLS handshake, the client obtains the functional agent's digital certificate, extracts its optional user name field, and compares it with the authenticated domain names in the list. If the comparison matches and the certificate chain verification passes, the final secure and encrypted business connection is established.
[0136] This embodiment, through the above-described scheme, provides a query interface based on business metadata and combines it with a local registry or dynamic discovery mechanism, enabling the navigation agent to achieve efficient aggregation and accurate matching of functional agents. It not only simplifies the client's discovery logic but also enhances the flexibility and scalability of the entire agent network through centralized management, serving as a crucial hub connecting clients with a massive number of functional agents.
[0137] For example, to help understand the implementation flow of the agent discovery method obtained by combining this embodiment with the above embodiment one, please refer to... Figure 2 , Figure 2 A simplified flowchart of an agent discovery method is provided, specifically: The client first sends a network access request message carrying a navigation agent configuration request to the DHCP server (step 1). Upon receiving the message, the DHCP server generates and returns a DHCP response message encapsulating the navigation agent's authentication domain name, IP address, and service parameters (step 2). After parsing the response message, the client establishes a secure transmission connection with the navigation agent based on the IP address (step 3). After the connection is established, the client sends an agent query request message carrying business metadata to the navigation agent through this secure channel (step 4). The navigation agent retrieves a list of matching functional agents based on the request and returns a list containing the authentication domain name, network address, and connection information of each functional agent to the client (step 5). After receiving the list, the client selects the target functional agent and initiates a secure connection establishment process based on its connection information (step 6). After successful verification, the client initiates business data interaction with the target functional agent (step 7), thus completing the entire process of trusted agent discovery and connection from network access to business invocation.
[0138] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the intelligent agent discovery method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0139] This application also provides an intelligent agent discovery device; please refer to [reference needed]. Figure 3 The intelligent agent discovery device includes: The access request sending module 301 is used to send a network access request message to the DHCP server, so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client. The transmission connection establishment module 302 is used to receive the DHCP response message sent by the DHCP server and establish a transmission connection with the navigation intelligent agent based on the DHCP response message; The query request sending module 303 is used to send an agent query request message to the navigation agent, so that the navigation agent can obtain the functional agent list information based on the agent query request message and send it to the client. The service connection establishment module 304 is used to receive the list information of the functional intelligent agents sent by the navigation intelligent agent, perform verification based on the list information of the functional intelligent agents, and establish a service connection between the client and the target functional intelligent agent after successful verification.
[0140] The agent discovery device provided in this application, employing the agent discovery method in the above embodiments, can solve the technical problems of insufficient security and reliability in the agent discovery process. Compared with the prior art, the beneficial effects of the agent discovery device provided in this application are the same as those of the agent discovery method provided in the above embodiments, and other technical features in the agent discovery device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0141] This application provides an agent discovery device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which are executed by the at least one processor to enable the at least one processor to perform the agent discovery method in Embodiment 1 above.
[0142] The following is for reference. Figure 4 The diagram illustrates a structural schematic suitable for implementing the intelligent agent discovery device in the embodiments of this application. The intelligent agent discovery device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 4 The intelligent agent discovery device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0143] like Figure 4As shown, the agent discovery device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory 1002 or a program loaded from a storage device 1003 into a random access memory 1004. The random access memory 1004 also stores various programs and data required for the operation of the agent discovery device. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 is also connected to the bus. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the agent discovery device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows agent discovery devices with various systems, it should be understood that implementing or possessing all of the systems shown is not required. More or fewer systems may be implemented alternatively.
[0144] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from read-only memory 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0145] The agent discovery device provided in this application, employing the agent discovery method described in the above embodiments, can solve the technical problems of insufficient security and reliability in the agent discovery process. Compared with the prior art, the beneficial effects of the agent discovery device provided in this application are the same as those of the agent discovery method provided in the above embodiments, and other technical features in this agent discovery device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0146] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0147] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0148] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the agent discovery method in the above embodiments.
[0149] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0150] The aforementioned computer-readable storage medium may be included in the agent discovery device; or it may exist independently and not be assembled into the agent discovery device.
[0151] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the agent discovery device, the agent discovery device causes the agent discovery device to: send a network access request message to a DHCP server, causing the DHCP server to generate a DHCP response message based on the network access request message and send it to the client; receive the DHCP response message sent by the DHCP server, and establish a transmission connection with the navigation agent based on the DHCP response message; send an agent query request message to the navigation agent, causing the navigation agent to obtain functional agent list information based on the agent query request message and send it to the client; receive the functional agent list information sent by the navigation agent, verify it based on the functional agent list information, and establish a service connection between the client and the target functional agent after successful verification.
[0152] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0153] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0154] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0155] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described agent discovery method, thereby solving the technical problem of insufficient security and reliability in the agent discovery process. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the agent discovery method provided in the above embodiments, and will not be repeated here.
[0156] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the agent discovery method described above.
[0157] The computer program product provided in this application can solve the technical problems of insufficient security and reliability in the process of intelligent agent discovery. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the intelligent agent discovery method provided in the above embodiments, and will not be repeated here.
[0158] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A method for discovering intelligent agents, characterized in that, The agent discovery method is applied to a client, and the agent discovery method includes: A network access request message is sent to the DHCP server, which then generates a DHCP response message based on the network access request message and sends it to the client. The DHCP response message includes extended options, which encapsulate the following fields: option code, option length, service priority, length and value of the authentication domain name of the navigation agent, length of the network address of the navigation agent and one or more IP addresses, and service parameters. The service parameters include an application layer protocol negotiation identifier and a port number. Receive the DHCP response message sent by the DHCP server, and establish a transmission connection with the navigation agent based on the DHCP response message; Send an agent query request message to the navigation agent so that the navigation agent can obtain the list of functional agents based on the agent query request message and send it to the client; The system receives the list of functional agents sent by the navigation agent, performs verification based on the list of functional agents, and establishes a business connection between the client and the target functional agent after successful verification. The step of receiving the DHCP response message sent by the DHCP server and establishing a transmission connection between the DHCP response message and the navigation agent includes: The extended options of the DHCP response message are parsed to extract the authentication domain name, network address, and service parameters of the navigation agent encapsulated in the extended options; Initiate a channel connection to the navigation agent through the network address, and obtain the digital certificate of the navigation agent during the channel connection process; Security verification is performed based on the digital certificate and the authentication domain name. After successful verification, a secure encrypted channel is established between the client and the navigation agent.
2. The agent discovery method as described in claim 1, characterized in that, The step of performing security verification based on the digital certificate and the authentication domain name, and establishing a secure encrypted channel between the client and the navigation agent after successful verification, includes: Extract the user-optional name field from the digital certificate; Based on the public key infrastructure root certificate store built into the client, the legitimacy and validity period of the trust chain of the digital certificate are verified; If the digital certificate is verified, the user's optional name field is compared with the authentication domain name. Once the comparison is successful, a secure encrypted channel is established between the client and the navigation agent.
3. The agent discovery method as described in claim 1, characterized in that, The steps of receiving the list of functional agents sent by the navigation agent, verifying based on the list of functional agents, and establishing a business connection between the client and the target functional agent after successful verification include: Parse the functional agent list information and extract the authentication domain name, network address and connection information of each functional agent entry in the functional agent list information; Based on the connection information, a service connection request is initiated to the target functional intelligent agent, and the digital certificate of the target functional intelligent agent is obtained during the service connection process; The digital certificate is securely verified based on the authentication domain name of the target functional agent. When the security verification is successful, a business connection is established between the client and the target functional agent.
4. The agent discovery method as described in claim 1, characterized in that, After the step of establishing a business connection between the client and the target functional agent upon successful verification, the following further includes: Monitor the connection status of the service connection; When an abnormal interruption is detected in the connection status of the service connection, an updated agent query request message is sent to the navigation agent, so that the navigation agent generates an updated list of functional agents based on the updated agent query request message and sends it to the client. The system receives the updated list of functional agents sent by the navigation agent, performs verification based on the updated list of functional agents, and establishes a business connection between the client and the updated target functional agent after successful verification.
5. A method for discovering intelligent agents, characterized in that, The agent discovery method is applied to a DHCP server, and the agent discovery method includes: The system receives a network access request message sent by a client and generates a DHCP response message based on the network access request message. The DHCP response message includes extended options, which encapsulate the following fields: option code, option length, service priority, length and value of the authentication domain name of the navigation agent, length of the network address of the navigation agent and one or more IP addresses, and service parameters. The service parameters include an application layer protocol negotiation identifier and a port number. The DHCP response message is sent to the client, so that the client establishes a transmission connection with the navigation agent based on the DHCP response message; The step of sending the DHCP response message to the client, so that the client establishes a transmission connection with the navigation agent based on the DHCP response message, includes: The DHCP response message is sent to the client, enabling the client to parse the extended options of the DHCP response message and extract the authentication domain name, network address, and service parameters of the navigation agent encapsulated in the extended options. The client then initiates a channel connection to the navigation agent through the network address and obtains the digital certificate of the navigation agent during the channel connection process. Security verification is performed based on the digital certificate and the authentication domain name. Upon successful verification, a secure encrypted channel is established between the client and the navigation agent.
6. A method for discovering intelligent agents, characterized in that, The agent discovery method is applied to a navigation agent, and the agent discovery method includes: The client receives an agent query request message from a client, obtains a list of functional agents based on the agent query request message, and establishes a transmission connection with the navigation agent based on a DHCP response message. The DHCP response message includes extended options, which encapsulate the following fields: option code, option length, service priority, length and value of the navigation agent's authentication domain name, length and one or more IP addresses of the navigation agent's network address, and service parameters. The service parameters include an application layer protocol negotiation identifier and a port number. The list of functional intelligent agents is sent to the client so that the client can verify based on the list of functional intelligent agents. After successful verification, a business connection is established between the client and the target functional intelligent agent. The client is further configured to establish a transmission connection with the navigation agent based on a DHCP response message. The DHCP response message includes extended options, which encapsulate the following fields: option code, option length, service priority, length and value of the navigation agent's authentication domain name, length of the navigation agent's network address and one or more IP addresses, and service parameters. The service parameters include an application layer protocol negotiation identifier and a port number. The client is also used to parse the extended options of the DHCP response message, extract the authentication domain name, network address and service parameters of the navigation agent encapsulated in the extended options; initiate a channel connection to the navigation agent through the network address, and obtain the digital certificate of the navigation agent during the channel connection process; perform security verification based on the digital certificate and the authentication domain name, and establish a secure encrypted channel between the client and the navigation agent after successful verification.
7. An intelligent agent detection device, characterized in that, The agent detection device includes: The access request sending module is used to send a network access request message to the DHCP server, so that the DHCP server generates a DHCP response message based on the network access request message and sends it to the client. The transmission connection establishment module is used to receive the DHCP response message sent by the DHCP server and establish a transmission connection with the navigation agent based on the DHCP response message; The query request sending module is used to send an agent query request message to the navigation agent, so that the navigation agent can obtain the functional agent list information based on the agent query request message and send it to the client. The service connection establishment module is used to receive the list information of the functional intelligent agents sent by the navigation intelligent agent, perform verification based on the list information of the functional intelligent agents, and establish a service connection between the client and the target functional intelligent agent after successful verification.
8. A smart agent discovery device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the agent discovery method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the agent discovery method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Verification method based on DHCP protocol and related equipment
CN115694856A
Method and device for trusted access of intelligent agent to intelligent agent internet by intelligent agent
CN121567379A
Mobile network-oriented agent management method, equipment and computer program product
CN121888229A